Nasa · Cryptolib · CVE-2026-79954
**Name of the Vulnerable Software and Affected Versions**
NASA CryptoLib version 1.5.0
**Description**
An authentication downgrade issue exists in the Telecommand (TC) receive path. The receiver selects the Security Association (SA) used for Space Data Link Security (SDLS) processing based only on the `SPI` field within the incoming frame, without verifying if the selected SA is authorized for the frame's `GVCID`.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.